HomeDefectsLIN1024-21631
Fixed

LIN1024-21631 : Security Advisory - linux - CVE-2026-45956

Created: May 28, 2026    Updated: Jun 1, 2026
Resolved Date: May 28, 2026
Found In Version: 10.24.33.2
Fix Version: 10.24.33.17
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()  vidi_connection_ioctl() retrieves the driver_data from drm_dev->dev to obtain a struct vidi_context pointer. However, drm_dev->dev is the exynos-drm master device, and the driver_data contained therein is not the vidi component device, but a completely different device.  This can lead to various bugs, ranging from null pointer dereferences and garbage value accesses to, in unlucky cases, out-of-bounds errors, use-after-free errors, and more.  To resolve this issue, we need to store/delete the vidi device pointer in exynos_drm_private->vidi_dev during bind/unbind, and then read this exynos_drm_private->vidi_dev within ioctl() to obtain the correct struct vidi_context pointer.

CVEs